Back to MDPositions

Privacy Policy

Last updated: May 2026

1. Introduction

MDPositions is a Shopify application published by FORTY & FREE (brand name: IDOW), a company registered in France under SIREN 925 005 753, located at 48 allée de Baceda, 59830 Bachy, France.

This Privacy Policy explains how we collect, use, and protect information when you use the MDPositions application.

2. Data we collect

MDPositions collects and processes the following data:

  • Shop information: your Shopify shop domain, used to identify your store and manage your subscription.
  • Product data: product titles, prices, inventory levels, sales data and other product attributes accessed via the Shopify API to perform sorting operations. This data is read in real time and is not stored in our database.
  • Collection data: collection IDs and titles you select for sorting. Only the Shopify IDs and titles are stored.
  • Sort configuration: your sorting rules, criteria, weights, pinned products and boosted vendors.
  • Billing information: your subscription plan and charge ID, managed entirely through the Shopify Billing API.

3. Data we do NOT collect

MDPositions does NOT collect, store, or process:

  • Customer personal data (names, emails, addresses, phone numbers)
  • Order details or customer purchase history
  • Payment or credit card information
  • Cookies or tracking data
  • Any data from your customers' browsers

We only access aggregated order count data (number of recent sales per product) via the Shopify API to calculate sales velocity for sorting. No individual order or customer data is stored.

4. How we use your data

The data we collect is used exclusively to:

  • Execute product sorting operations on your selected collections
  • Manage your subscription plan and billing
  • Provide automatic scheduled sorting via cron
  • Notify the publisher of paid subscription activations and uninstalls (transactional internal use only)
  • Improve and maintain the application

5. Data storage and security

Sort configurations and shop settings are stored in a PostgreSQL database hosted on secure servers in the European Union (Render Frankfurt region). All communications between the app, Shopify and our infrastructure use HTTPS/TLS encryption. We do not share, sell or transfer your data to any third party.

6. Data retention and deletion

Your data is retained as long as the application is installed on your shop. When you uninstall MDPositions, your runtime data (sessions, sort rules, cron tokens, plan) is deleted immediately. Telemetry events are kept for audit and removed when Shopify sends the shop/redact webhook (typically 48 hours after uninstall).

You can request complete data deletion at any time by contacting us or by uninstalling the application.

7. GDPR compliance

As a company based in the European Union, we comply with the General Data Protection Regulation (GDPR). We implement the three mandatory Shopify GDPR webhooks:

  • Customer data request: we confirm that no personal customer data is stored.
  • Customer data erasure: we confirm that no personal customer data needs to be erased.
  • Shop data erasure: all shop-related data is permanently deleted upon request.

8. Shopify API scopes

MDPositions requests the following Shopify API permissions:

  • read_products / write_products: to read product data and reorder products in collections.
  • read_orders: to calculate sales velocity (aggregated product sales count only).
  • read_inventory: to read inventory levels for stock-based sorting criteria.

9. Contact

For any question regarding this privacy policy or your data, please contact us:

FORTY & FREE (IDOW)
48 allée de Baceda, 59830 Bachy, France
SIREN: 925 005 753
contact@fortyandfree.fr